Cyber Resilience Act: the risk assessment manufacturers need
The Cyber Resilience Act (CRA) sets cybersecurity requirements for almost every hardware and software product with digital elements sold in the EU. At its core is a documented cybersecurity risk assessment. This guide covers who is affected, the key dates and what the assessment must contain.
Who is affected
The CRA applies to products with digital elements — hardware and software that connect, directly or indirectly, to a device or network. Manufacturers carry most obligations, but importers and distributors have duties too. Some sectors with their own rules, such as medical devices, motor vehicles and aviation, are excluded.
Key dates
- 10 December 2024 — the regulation entered into force.
- 11 June 2026 — Chapter IV on the notification of conformity assessment bodies applies.
- 11 September 2026 — Article 14 applies: manufacturers must report actively exploited vulnerabilities and severe incidents.
- 11 December 2027 — the rest of the regulation applies (Article 71), including the essential requirements and CE marking.
The risk assessment requirement
Article 13(2) and (3) require manufacturers to assess the cybersecurity risks of a product and take the result into account during planning, design, development, production, delivery and maintenance. The assessment must state which essential requirements of Annex I apply and how they are implemented, based on the product's intended purpose and reasonably foreseeable use.
The assessment is part of the technical documentation (Annex VII). It must be kept up to date during the support period.
Product categories
Most products can be self-assessed by the manufacturer. Important products (Class I and Class II, Annex III) and critical products (Annex IV) need a harmonised standard, a third-party assessment or a certification scheme, depending on the class.
How Zybercomply helps
Zybercomply follows the risk management workflow of the draft standard prEN 40000-1-2, which is being developed for the CRA: context and scope, assets and security needs, acceptance criteria, STRIDE threats, ETSI TS 102 165-1 scoring, treatment and monitoring. The output — risk register, treatment decisions and coverage report — slots straight into your technical documentation.
Frequently asked questions
- What is the Cyber Resilience Act?
- The Cyber Resilience Act (Regulation (EU) 2024/2847) is an EU regulation that sets mandatory cybersecurity requirements for products with digital elements throughout their lifecycle.
- When does the Cyber Resilience Act apply?
- It entered into force on 10 December 2024. Vulnerability and incident reporting applies from 11 September 2026, and the remaining obligations from 11 December 2027.
- Is a risk assessment mandatory under the CRA?
- Yes. Article 13(2) and (3) require manufacturers to carry out a cybersecurity risk assessment and include it in the technical documentation.
- Which standard supports the CRA risk assessment?
- Harmonised standards for the CRA are still being developed by CEN, CENELEC and ETSI. The draft prEN 40000-1-2 describes cybersecurity risk management for products with digital elements and is the basis of Zybercomply's workflow. Until standards are cited in the Official Journal, they give no presumption of conformity.
- Does the CRA replace the RED cybersecurity requirements?
- Yes. Delegated Regulation (EU) 2026/339 repeals the RED cybersecurity delegated act (EU) 2022/30 from 11 December 2027, when the CRA applies in full. Until then, radio equipment must meet the RED requirements, for example through EN 18031.